Code review exercise · 8 MIN
Review an AI-generated change
Inspect a short endpoint. Decide what evidence you need before you accept the change.
The situation
An AI assistant proposes an invoice endpoint. A signed-in user must only see invoices from their own organization. You are reviewing the change before it can be released.
What to do
- Read the code and its plain-language explanation. You do not need to run it.
- Select every check needed before acceptance. Check your answers, read the reasons, and try again if a check is missing.
You review this PR. The feature must return an invoice only to an authenticated user in the same organization. The extract is incomplete.
// Fictional, incomplete example. Do not deploy.
app.get('/invoices/:id', async (req, res) => {
const invoice = await db.invoice.findUnique({
where: { id: req.params.id }
});
console.log('Invoice response', invoice);
return res.json(invoice);
});What does the code do?
The endpoint takes an invoice ID from the request, fetches that invoice, logs the complete invoice, and returns it. The extract does not show who checks the user’s right to this invoice.
Authentication checks who the user is. Authorization checks what the user may do. Middleware is code that processes the request before this endpoint. It can contain checks absent from this extract.
TO FINISH
Does a successful request prove that the invoice endpoint is safe?
Compare your answer with the explanation
No. It proves that one request worked. You also need evidence that a user cannot read another organization’s invoice. Inspect the complete request path, missing-record behavior, and logging. A successful test must cover the requirement that matters.
Use this at work
In your next PR review, add one test for an action that must be denied.
Choose another exercise